With 1,000+ intelligence professionals serving over 1,900 clients worldwide, Recorded Future is the world’s most advanced, and largest, intelligence company!
The Research on Request Team at Recorded Future is looking for a Threat Intelligence Analyst to assist in producing consistently high quality cyber threat intelligence to clients based on their specific intelligence requirements. This production will likely involve the review and analysis of infrastructure associated with a specific threat actor or campaign, or analysis of indicators associated with a specific incident. In addition, this analysis will be expected to produce analysis in line with more general requirements, such as research into overall threats to an industry, region, or technology. The analyst will be primarily responsible for ad hoc intelligence requests. Writing either ad hoc or regular reports requires the ability to work with or automate regularly recurring datasets, while also requiring flexibility to quickly research and analyze a broad spectrum of cyber threat activity, from new attacks against automotive technology to patterns in malware development.
What You’ll Do :
- Produce and review finished intelligence reports that address clients’ priority intelligence requirements across a broad range of cyber threat activity topics
- Research indicators of threat activity in the form of netflow / networking data, website / domain / IP infrastructure, security tooling logs, and email metadata
- Engage with clients across report lifecycle : initial scoping, finished intelligence delivery, and follow‑up review / support
- Develop novel, automated, or simpler processes for research and analysis
- Work on projects across multiple research teams with sometimes tight deadlines
What You’ll Bring :
2+ years experience as a threat intelligence analyst or in similar positionBA / BS or MA / MS degree or equivalent experience in Computer Science, Information Security, or a related fieldStrong understanding of TCP / IP, DNS, HTTP / S, SMTP, and common application‑layer protocolsAbility to analyze netflow data (e.g., source / destination IPs, ports, protocols, volumes, timing)Familiarity with routing, ASNs, CIDR, and IP ownership (WHOIS, RIRs)Experience investigating malicious domains, URLs, and IP addressesFamiliarity with attacker infrastructure patterns (e.g., fast‑flux, bulletproof hosting, VPS abuse, CDNs, domain generation algorithms)Ability to pivot across infrastructure artifacts to identify related activityUnderstanding of email headers and metadata (SPF, DKIM, DMARC, Message‑ID, Received headers)Experience analyzing phishing, spoofing, and campaign‑level email infrastructurePractical experience using common threat intelligence analysis models such as MITRE ATT&CK, the Diamond Model, and the Cyber Kill ChainFamiliarity with and use of common cyber threat intelligence tools such as DomainTools, VirusTotal, SHODAN, etc.Demonstrable experience researching and analyzing cyber threats across either a) multiple industries or b) multiple timeframes, including but not limited to finance, manufacturing, IT services, healthcare, and public sectorManaging client expectations based on pre‑established scope of work and delivery timeframeAbility to convey complex technical and non-technical concepts with intent of delivering value to each clientExcellent writing skills are mandatory, to be assessed via a writing samplePreferred Qualifications :
Ability to analyze malware samples, including both static and dynamic analysisWorking knowledge of at least one language other than English, with relevance preferred for regions with more active or sophisticated cyberattackersExperience working with clients to produce intelligence requirements, or reports / research in line with such requirementsDemonstrable experience of conducting cyber threat investigationsWhy Should You Join Recorded Future?
Recorded Future employees (or “Futurists”) represent over 40 nationalities and embody our core values of having high standards, practicing inclusion, and acting ethically. Our dedication to empowering clients with intelligence to disrupt adversaries has earned us a 4.6‑star user rating on G2 and more than 50% of Fortune 100 companies as customers.
#J-18808-Ljbffr